CISA republished Mitsubishi Electric advisories for two high-severity denial-of-service vulnerabilities affecting industrial control products in the MELSEC iQ-F Series. The flaws impact the FX5-EIP EtherNet/IP Module (CVE-2026-8805) and the FX5-ENET/IP Ethernet Module (CVE-2026-8806), both used in critical manufacturing environments. In the FX5-EIP module, a remotely reachable integer overflow in the EtherNet/IP function can be triggered by rapidly opening many TCP connections, leading to inconsistent connection handling and improper memory access. In the FX5-ENET/IP module, an expected-behavior violation can be exploited by flooding the Ethernet port with a large volume of packets, overloading processing and stopping communications while disabling internal anomaly-detection processing.
CISA and Mitsubishi rated both issues High severity, with CVE-2026-8806 carrying a CVSS v4.0 score of 8.7 and affecting all versions of the FX5-ENET/IP module, while CVE-2026-8805 affects version 1.000 and earlier of the FX5-EIP module. Recommended mitigations include applying vendor fixes where available, minimizing network exposure, isolating control systems behind firewalls, restricting access with segmentation and secure remote connectivity such as updated VPNs, and monitoring for abnormal traffic or excessive connection attempts. The disclosures follow earlier CISA advisories involving Mitsubishi MELSEC networking components, including an authentication-bypass issue in the WS Series Ethernet interface module (CVE-2023-1618).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-616 urging users and administrators to review Mitsubishi Electric’s June 18, 2026 security advisories and apply the necessary updates for affected MELSEC iQ-F Series networking modules. The notice covered denial-of-service issues affecting the FX5-EIP EtherNet/IP Module and FX5-ENET/IP Ethernet Module.
CVE-2026-8806 was published as a high-severity denial-of-service vulnerability affecting Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module devices. The entry describes packet flooding of the Ethernet port as the attack method and recommends firmware updates, traffic monitoring, and network access restrictions.
CISA republished a Mitsubishi Electric advisory for CVE-2026-8806 affecting the MELSEC iQ-F Series FX5-ENET/IP Ethernet Module in all versions. The vulnerability allows a remote unauthenticated attacker to flood the Ethernet port with packets, causing excessive processing load and denial of service.
CISA republished a Mitsubishi Electric advisory for CVE-2026-8805 affecting the MELSEC iQ-F Series FX5-EIP EtherNet/IP Module version 1.000 and earlier. The flaw is a remotely triggerable integer overflow or wraparound issue that can cause denial of service through rapid opening of many TCP connections.
CISA published advisory ICSA-24-030-03 covering a Mitsubishi Electric MELSEC WS Series Ethernet Interface Module issue. The reference provides no synopsis, so no further event details are available from the source content.
CISA published Update A for its advisory on Mitsubishi Electric MELSEC WS Series Ethernet interface modules, describing CVE-2023-1618 as a remotely exploitable authentication bypass vulnerability. CISA said no known public exploitation specifically targeting the flaw had been reported at the time of the advisory.
Mitsubishi Electric released fixed versions for the MELSEC WS Series WS0-GETH00200 Ethernet interface module to address CVE-2023-1618, an authentication bypass caused by an active debug code and default-enabled hidden telnet function. The vendor also advised setting a strong telnet password and restricting access through firewalls, VPNs, LAN segmentation, and physical controls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecwe.mitre.org
Open sourcemitsubishielectric.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.